Restricting AKS API server access to specific networks is done with authorized IP address ranges

Plan and implement advanced security for compute
Answer Correct answer: A — Configure authorized IP address ranges on AKS1 to allow API server access only from specific networks with minimal effort.

You have an Azure subscription that contains an Azure Kubernetes Service (AKS) cluster named AKS1. You have an Azure container registry that stores container images that were deployed by using Azure DevOps Microsoft-hosted agents. You need to ensure that administrators can access AKS1 only from specific networks. The solution must minimize administrative effort. What should you configure for AKS1?

  1. authorized IP address ranges Correct Answer
  2. an Application Gateway Ingress Controller (AGIC)
  3. a private endpoint
  4. a private cluster

Community Votes

A
57%
C
43%

57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Authorized IP ranges are the lightweight, built-in control for 'access only from specific networks'. A private cluster or private endpoint changes the network topology and costs more to operate; the question's 'minimize administrative effort' points to authorized IP ranges.

To let administrators reach the AKS API server only from specific networks, you configure authorized IP address ranges on the cluster. This lets you allowlist the IP ranges (such as your admin jump-host or corporate CIDR) that can reach the Kubernetes API server, with minimal operational overhead.

Candidates pick a private cluster or private endpoint, but those isolate the API server on a private network rather than allowlisting specific admin networks; the direct 'only from specific networks' control is authorized IP address ranges.

Community Discussion (7 comments)

Codelawdepp 👍 9
correct answer is A: "authorized IP address ranges " restricts access to specific IP addresses for reference: https://learn.microsoft.com/en-us/azure/aks/api-server-authorized-ip-ranges?tabs=azure-cli B: an Application Gateway Ingress Controller (AGIC): No because it's manages ingress traffic via Azure Application Gateway. C. a private endpoint: No because it's establishes a private connection through the Azure network. D. a private cluster: No because it's limits API server access to a private virtual network.
dc864d4 👍 5
This was on the test 5/25/2024
JBAnalyst 👍 1 Selected: C
Private endpoint https://learn.microsoft.com/en-us/azure/aks/private-clusters?tabs=default-basic-networking%2Cazure-portal#use-a-private-endpoint-connection
cassucena 👍 1 Selected: A
"authorized IP address ranges " restricts access to specific IP addresses, private enpoints lets you connect with ip that has access to the subnet.
Viggy1212 👍 1 Selected: A
By using a private cluster, you can ensure network traffic between your API server and your node pools remains only on the private network. Source : https://learn.microsoft.com/en-us/azure/aks/private-clusters?tabs=default-basic-networking%2Cazure-portal Question is about ensuring that administrators can access AKS1 only from specific networks, which means you have to use "authorized IP address ranges"
St33lth 👍 2 Selected: A
Answer A is correct
JovenesPromesasMS 👍 2 Selected: C
https://learn.microsoft.com/en-us/azure/aks/private-clusters?tabs=azure-portal

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Authorized IP address ranges let you specify the CIDR ranges permitted to access the AKS API server. When you need administrators to reach AKS1 only from certain networks and want to minimize effort, enabling authorized IP ranges is the targeted, built-in solution. (Option A)

Why the Other Options Are Wrong

  • Option B (Application Gateway Ingress Controller) manages ingress traffic to workloads, not administrative access to the API server.
  • Option C (Private endpoint) is a connectivity mechanism; it does not by itself restrict access to specific admin networks and adds setup overhead.
  • Option D (Private cluster) places the API server on a private network, which is heavier to operate than simply allowlisting IP ranges and is not the minimal-effort answer the question seeks.

Community Comment Notes

Top comment (9 likes) cited the AKS authorized-IP-ranges doc: 'authorized IP address ranges restricts access to specific IP addresses,' confirming A.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide